Settings
Configure your organization's team members, API keys, branding, and vendor-review policy.
Overview
The Settings section allows administrators to:
- Manage team members and invite users
- Configure your Anthropic API key for Bring-Your-Own-Key (BYOK) usage
- Upload a custom organization logo (plan-dependent)
- Govern vendor security requirements, AI instructions, review mode, and document retention across parent and child organizations
- Choose whether vendor-review source documents are deleted after initial analysis
Write access depends on both your role and the selected organization's governance mode. Read-only administrators can view settings but cannot change them. A child administrator can change vendor settings only when the parent organization has selected Child organization manages its settings for that child.
Accessing Settings
- Log in at https://app.canirunthat.com
- Click Settings in the main navigation menu
- Use the available settings cards for your role and organization
Logo Branding
Custom Logo Upload
The Branding card allows you to upload a custom logo for your organization:
- Logo Upload — Upload your company logo (PNG, JPG, or GIF format)
- Maximum file size: 5 MB
- Recommended: Square format for best appearance
- Logo Display — How your logo appears in the platform depends on your plan:
- Tier 2 Plan: Logo displays alongside the application name
- Tier 3+ Plan: Logo fully replaces the application branding
Uploading a Logo
- Go to Settings > Branding card
- Click Upload Logo and select a PNG, JPG, or GIF file from your computer (max 5 MB)
- Click Upload Logo to confirm the upload
- Once uploaded, a preview of your logo will display in the card
Deleting a Logo
To remove your custom logo:
- Go to Settings > Branding card
- If a logo is already uploaded, a Delete Logo button will appear
- Click Delete Logo to remove the custom branding
- Confirm the deletion when prompted
Plan Availability
Logo branding requires Tier 2 or higher plan tier. If branding is unavailable, you'll see a message like:
Logo branding is not available on your current plan.
Upgrade to Tier 2 or higher to customize your organization's logo.
Contact your administrator to upgrade your plan.
Anthropic API Key (BYOK)
Overview
The Anthropic API Key card allows you to configure your own Anthropic API key for Bring-Your-Own-Key (BYOK) usage. When configured, your key is used for all security analysis in your organization.
Saving Your API Key
- Go to Settings > Anthropic API Key card
- In the Anthropic API Key password input field, enter your API key
- Key format must start with
sk-ant-
- Key format must start with
- Click Save Key
- A success message shows "API key saved successfully"
- Your key status updates to show "Configured — sk-ant-***xxxx" (masked)
Key Management
The Current Status field shows:
- Configured — Your key is saved and active. A masked preview is displayed (e.g.,
sk-ant-***xxxx) - Not configured — No key is currently set. Configure one to enable BYOK usage
Plan and Source Restrictions
- BYOK not available: If you see "API key management is not available on your current plan," your organization doesn't support BYOK yet
For complete BYOK setup instructions and troubleshooting, see the BYOK Guide.
Vendor Settings Across Parent and Child Organizations
Vendor settings are one governed bundle containing:
- Vendor security requirements
- Vendor AI instructions
- Vendor review mode
- Vendor review document retention
Parent organization settings are the default for every child organization. Parent administrators use the Organization dropdown in the Vendor Settings Scope card to select the parent or an active child. The four vendor settings cards below the selector always show the effective bundle for that selection.
Child Governance Modes
For each child, a parent administrator can select one of three modes:
| Mode | Effective settings | Who can change them |
|---|---|---|
| Follow parent organization | The parent's current bundle, updated dynamically whenever the parent changes it | Parent administrators edit the parent bundle; the child view is read-only |
| Child organization manages its settings | A separate child-specific bundle | Child administrators and parent administrators |
| Parent manages child-specific settings | A separate child-specific bundle | Parent administrators only; child users can view it |
Changing between the two custom modes preserves the child's existing bundle. Returning to Follow parent organization makes the custom bundle dormant rather than deleting it, so it is available if custom control is enabled again later.
Initial Settings for a Custom Child Bundle
The first time a child moves from Follow parent organization to either custom mode, the parent administrator chooses one initialization source:
- Copy the parent organization's current settings — Copies the parent's current AI instructions, review mode, retention setting, and active security requirements.
- Start from RepoRisk platform defaults — Starts with no custom AI instructions, Chill Mode, source-document retention enabled, and a point-in-time copy of the active platform security requirement library.
This is a one-time initialization choice. Later governance changes preserve the initialized bundle and its original source. If no active platform requirements are available, RepoRisk does not create a partial child bundle; the administrator can retry after the platform library is available.
Vendor reviews resolve settings from the vendor's persisted parent and child ownership when analysis starts. Changing a browser dropdown cannot redirect an existing vendor review to another organization's policy.
Vendor Security Requirements
The Vendor Security Requirements card defines the controls used to evaluate vendor documentation. Administrators with write access to the selected scope can:
- Add, edit, and deactivate requirements
- Assign Deal Breaker, Highly Desired, Preferred, or Optional severity
- Import selected controls from the recommended platform library
- Extract proposed requirements from policy text, PDF, DOCX, or TXT files and review them before import
When a child follows the parent, it always uses the parent's current active requirements. A custom child bundle receives its own materialized requirement set and no longer combines parent and child rows at runtime.
Vendor AI Instructions
The Vendor AI Instructions card lets an administrator with write access provide organization-specific context that is included during vendor security analysis.
When to Use
Use this field to tailor vendor evaluations to your organization's policies and risk appetite:
- State your compliance framework (e.g., "We follow SOC 2 Type II and HIPAA")
- Call out vendor categories requiring stricter review
- Specify certifications or contractual clauses your procurement policy mandates
- Provide industry-specific context the AI should consider
Configuring Vendor AI Instructions
- Go to Settings > Vendor AI Instructions card
- Enter your context text in the textarea (up to 4,000 characters)
- Click Save Instructions
- A success message confirms the instructions are saved
All future vendor analysis runs will include this context in the AI evaluation prompt.
Clearing Instructions
To remove the instructions, clear the textarea and click Save Instructions.
Vendor Review Mode
The Vendor Review Mode card controls how the AI evaluates vendor evidence:
- Chill Mode — The platform default. Evaluates whether the evidence meets the intent of each requirement and focuses follow-up questions on material gaps or warning signs.
- Strict Mode — Applies more rigorous scrutiny to qualifiers, scope limitations, and alternative controls.
The effective mode is resolved when each analysis task starts. A custom child bundle can therefore use a different review mode from its parent without changing the parent's reviews.
Vendor Review Document Retention
Administrators with write access to the selected scope can use the Vendor Review Document Retention card to reduce retained source data:
- Go to Settings > Vendor Review Document Retention.
- Enable Delete source documents after initial analysis.
- Review the permanent-deletion warning and click Save.
Delete source documents after initial analysis is off in the platform defaults, so vendor review documents are retained by default. The setting applies only to vendor reviews created after the change is saved. Each review keeps the effective setting that was active when that review was created. Enabling or disabling it later does not change existing reviews and does not delete historical documents.
When enabled, documents remain available throughout upload, text extraction, and initial AI analysis. RepoRisk first saves the initial findings, summary, recommendation, and generated questions. It then permanently deletes the source objects from document storage. Metadata, citations, findings, questions, responses, and audit history remain available.
Deleted source files cannot be viewed, downloaded, or restored. Follow-up questions and response analysis use the saved questions, findings, responses, organization context, and summary instead of revisiting the original documents. Follow-up quality may therefore be degraded.
Read-only administrators can view this setting but cannot change it. A child administrator can change it only in Child organization manages its settings mode.
Best Practices
Security Best Practices
- Upload Organization Logo — Add your company logo to personalize the platform (if your plan supports it)
- Manage Team Access Carefully — Grant admin role only to trusted team members who need Settings access
- Rotate API Keys — Regularly update your Anthropic API key for security
- Audit Team Membership — Periodically review team members and remove inactive or departed accounts
Operational Best Practices
- Keep Logo Current — Update your organization logo if you rebrand
- Review Team Members Regularly — Ensure team member roles still match their current responsibilities
Troubleshooting
Settings Changes Not Saved
If your changes don't save:
- Ensure all required fields are filled
- Click Save and wait for a confirmation message
- Refresh the page and verify the changes took effect
- Contact Support if the issue persists
Child Vendor Settings Are Read-Only
Check the governance explanation in Vendor Settings Scope:
- Follow parent organization means the child is dynamically using the parent bundle.
- Parent manages child-specific settings means only a parent administrator can modify the child bundle.
- A read-only administrator cannot make changes in any mode.
Only a parent administrator can change a child's governance mode.
API Key Validation Failed
See the BYOK Troubleshooting guide for help with API key issues.
Cannot Access Settings
If you see "You do not have permission to access Settings":
- You must be an admin user to access Settings
- Contact your organization administrator to request admin access
- Ask your administrator to upgrade your role from Member to Admin
Next Steps
- Manage Team Members — Invite team members and configure roles in Team Management
- Configure BYOK — Set up your own Anthropic API key in BYOK Configuration
- Run Vendor Reviews — Use vendor AI instructions and security requirements in Vendor Security Review
- Manage Child Organizations — Review membership, BYOK, branding, and isolation behavior in Sub-Organizations